2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-24460HIGH7.8Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated ...
CVE-2023-40297HIGH7.5Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.
CVE-2023-5938HIGH8.9Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable ...
CVE-2023-5936HIGH7.8On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a mali...
CVE-2023-5935HIGH7.4When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process....
CVE-2023-6324HIGH8.8ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
CVE-2023-6322HIGH8.8A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE ver...
CVE-2023-6321HIGH8.8A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to ...
CVE-2023-33327HIGH8.8Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This is...
CVE-2023-46714HIGH7.2A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 ...
CVE-2023-45583HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, Forti...
CVE-2023-44247HIGH7.2A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker...
CVE-2023-40720HIGH7.1An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 throug...
CVE-2023-46280HIGH8.2A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All ve...
CVE-2023-35841HIGH7.8Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which a...
CVE-2023-49781HIGH7.6NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability...
CVE-2023-47712HIGH7.8IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due ...
CVE-2023-47709HIGH8.8IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary comman...
CVE-2023-46870HIGH7.3extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Blu...
CVE-2023-38264HIGH7.5The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21...
CVE-2023-26566HIGH8.6Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which a...
CVE-2023-40490HIGH7.8Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2023-35757HIGH8.8D-Link DAP-2622 DDP Set Date-Time NTP Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulne...
CVE-2023-35749HIGH8.8D-Link DAP-2622 DDP Firmware Upgrade Filename Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...
CVE-2023-35748HIGH8.8D-Link DAP-2622 DDP Firmware Upgrade Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now